The first module moved onto the new build process. It named a placeholder digest nothing could produce, so it only ever worked where somebody had pre-built its image by hand. It names the two shared bases instead, and the mesh builds it. Chosen first deliberately: it requires nothing, nothing requires it, and an audit trail of every event on the mesh is the thing most worth having while modules are being moved one at a time.
34 lines
2.0 KiB
Docker
34 lines
2.0 KiB
Docker
# audit-logger's runtime: the shared runtime image, carrying this module's compiled code.
|
|
#
|
|
# **Built from this module's own directory and nothing else.** The toolkit is in the base image, so
|
|
# nothing is copied out of a neighbouring checkout — which is what lets the mesh build this from a
|
|
# repository and a path (novox/hq ADR 0069) rather than only on a workstation that happens to have
|
|
# the siblings laid out beside it.
|
|
|
|
# Two bases, named rather than pinned: the image this is COMPILED in, and the image it RUNS in.
|
|
# They are different images on purpose — the first carries a compiler and the second must not, or
|
|
# every running container would carry one it never invokes. The mesh answers both with the copies it
|
|
# holds, because a fingerprint written here would name one particular copy and no other mesh has it
|
|
# (novox/hq issue 044). Declared in module.json's `build.on`; deliberately no defaults, so a build
|
|
# nobody told stops here and says which module to build first.
|
|
ARG BUILD_BASE
|
|
ARG RUNTIME_BASE
|
|
|
|
FROM ${BUILD_BASE} AS build
|
|
# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own
|
|
# node_modules — the module is compiled against exactly the toolkit it will run against.
|
|
WORKDIR /app/modules/audit-logger
|
|
COPY . .
|
|
# The compiler is invoked by its real path rather than through node_modules/.bin, whose entries are
|
|
# symlinks to a launcher that requires its library relatively — resolved away when the base image
|
|
# was assembled.
|
|
RUN node /app/node_modules/typescript/bin/tsc audit.ts index.ts \
|
|
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
|
|
FROM ${RUNTIME_BASE}
|
|
COPY --from=build /app/modules/audit-logger/dist /app/modules/audit-logger/dist
|
|
# **Served, not run.** This subscribes on import, and the serve mode binds the broker before it
|
|
# imports anything — `run` exists for a step that works offline and exits, and would leave this
|
|
# with nothing to subscribe to.
|
|
ENV MESH_TOOL_MODULES=/app/modules/audit-logger/dist/index.js
|